Storm-1175's Zero-Day Rampage: China Hackers Dropping Medusa Ransomware in Record Time
Ever wonder why your firewall feels like a screen door against pros? China-based Storm-1175 is chaining zero-days to unleash Medusa ransomware faster than you can say 'patch Tuesday.'
Threat DigestApr 07, 20263 min read
⚡ Key Takeaways
Storm-1175 exploits zero-days like CVE-2025-10035 pre-disclosure for ultra-fast Medusa ransomware deployment.𝕏
RMM tools are prime for abuse — attackers blend in via trusted platforms like ScreenConnect.𝕏
Healthcare, finance, education hit hardest; patch gaps let them rotate vulns rapidly.𝕏
The 60-Second TL;DR
Storm-1175 exploits zero-days like CVE-2025-10035 pre-disclosure for ultra-fast Medusa ransomware deployment.
RMM tools are prime for abuse — attackers blend in via trusted platforms like ScreenConnect.
Healthcare, finance, education hit hardest; patch gaps let them rotate vulns rapidly.